DPIAC March 21, 2007 Morning Minutes
Total Page:16
File Type:pdf, Size:1020Kb
DEPARTMENT OF HOMELAND SECURITY DATA PRIVACY AND INTEGRITY ADVISORY COMMITTEE FULL COMMITTEE MEETING WEDNESDAY, March 21, 2007 Crowne Plaza Washington National Airport Arlington Ballroom 1480 Crystal Drive Arlington, VA 22202 MORNING SESSION MS. RICHARDS: Good morning everybody. My name is Becky Richards. Iʹm the Executive Director of the DHS Data Privacy and Integrity Advisory Committee at least until 5:30 at which point we will be turning it over to someone else. So with this we begin this meeting. MR. BEALES: Thank you Becky and welcome everyone to our public meeting today. If you would, please be sure your cell phones are turned off. That would be helpful to all of us. If you are interested in signing up for public comments please do so with Tamara back at the registration table by where you came in. As is our custom weʹll have a public comment opportunity at the end of the meeting, but you do need to sign up. There are meeting materials on the table in the back of the room here. There is a bound document with a cover for the REAL ID Privacy Impact Assessment. That actually includes all of the DHS‐related materials. The copying company bound them all together. So itʹs a package deal. You have to take all the DHS stuff or nothing. We will begin this morning by hearing from the DHS Privacy Office. Hugo Teufel is the Chief Privacy Officer, but he is testifying in front of the Senate Appropriations Committee this morning. He thought that was a higher calling than us and I canʹt DHS Data Privacy And Integrity Advisory Committee: March 21, 2007 Official Meeting Minutes disagree, and so we will hear from Ken Mortensen today whoʹs the Acting Chief of Staff in the Privacy Office. Welcome Ken. MR. MORTENSEN: Thank you very much Howard and thank you very much to the committee. Itʹs wonderful to see you all again and as Howard mentioned, Hugo is testifying this morning up on the Hill in front of the Appropriations Committee talking about privacy operations within the department relating to our funding. And unfortunately he sends his regrets. He would like to be here, but when the Hill calls we do like to be able to answer them as well. What I thought Iʹd do is provide you with an update as to what has occurred since we last met in Miami on December the 5th and explain some of the things that have changed and also explain some of the things that were in process but have finalized since then. The first thing I would like to talk about is the structure of the Privacy Office. You may recall that Hugo mentioned that he was in the process of restructuring the office into two main functionalities: a privacy functionality and a FOIA functionality. In Miami you heard from Catherine Papoi who is the Deputy Chief FOIA Officer for the office and since we met we have brought on a full contingent of FTEs to support her, two associate directors, one that focuses specifically on the processing of FOIA requests received in by the department for headquarters operations for which we are responsible of processing those particular FOIA requests and another associate director whose job is to coordinate and manage the policy and programs both from a cross‐cutting sense, for example, we may have many FOIA requests that touch many different parts of the department, will be requests for documents that will come out of different components as well as trying to unify and harmonize the policies with regard to disclosure throughout the department, one of the key things that Hugo is attempting to do. All of this is being done to establish the function so that we are able to respond better to the disclosure operations which weʹve always discussed in the Privacy Office as being the third pillar, the Freedom of Information Act is the third pillar of privacy which is also supported by the Executive Order 13392 in which the President asked all federal departments to look at their FOIA processing disclosure processes, and that is part of what is being accomplished there. On the privacy side we took a look at what our organic statute required us to do. Section 222 of the Homeland Security Act has certain specific duties that are assigned to the privacy officer for the department. Those duties are ones that you are familiar with. The first one is that we have the duty to ensure that the technology used by the department sustains and does not erode the privacy protections of individuals. Second duty is to ensure that the systems and records that are maintained by the department are done so in compliance with the Privacy Act of 1974. The third duty is for us to review the impact of legislation ‐ federal legislation and regulation as it relates to the collection, use and dissemination of personal information throughout the federal government. The DHS Data Privacy And Integrity Advisory Committee: March 21, 2007 Official Meeting Minutes fourth one deals with doing privacy impact assessments on the rulemakings of the department to understand the impact that those have on personal privacy. The fifth and sixth ones deal with coordination with the Office of Civil Rights and Civil Liberties and our reporting functionality to the Congress on our annual report. With regard to those particular functions what weʹve done is weʹve kind of realigned although we really havenʹt changed the structure much in that weʹve looked at those in terms of what was being accomplished. We now have four major sub‐ functions if you will within privacy. Some of them youʹre familiar with. We have compliance which Becky Richards is the Director for Privacy Compliance throughout the department. We have International Affairs. John Kropf who youʹve met in the past is the Director for International Privacy Policy. We have technology. Peter Sand is the Director of Privacy Technology. And the new one which is the Director for Legislative and Regulatory Affairs which is Ken Hunt who you will meet later today. In addition to the duties of Subsection 4 which was the privacy impact assessments of the rulemakings of the department which Ken will be responsible for and also Subsection 3, reviewing legislation and regulation across the federal government. Kenʹs duties will also include being the Executive Director of your committee. So Ken will be the new Becky, although obviously will not replace her in your hearts. Ken is also going to be the Executive Secretary for the Data Integrity Board which is an official internal board required under the Privacy Act with regard to the approval and processing through the departmental matching agreements. So Ken has a very large amount on his plate. In fact he basically had a baptism of fire. As I will mention a little bit later weʹve had two Hill hearings and a number of briefings that weʹve been doing in the last month. Ken has been running around getting together all the testimony and supporting briefing materials for that. So the new structure weʹre hoping will also to be able to better meet the needs and our duties under Section 222 and allow us to be able to apply what we are learning to the programs within the department appropriately. And as you will hear today one of those things has already occurred with regard to the REAL ID implementation, the notice of proposed rulemaking that went out and the PIA that we promulgated and was approved by our office this past March 1 when the notice of proposed rulemaking came out. That was the exercise of our duties under Subsection 4 where we reviewed the rulemaking and we put out a privacy impact assessment on that rulemaking itself. As I mentioned Hugo is testifying today. Today his testimony is in front of the Appropriations Committee mainly looking at budget issues, but also trying to understand the privacy operations within the department. So he will be talking specifically about some of the things that we are doing with regard to operations. Last week Hugo was in front of the Subcommittee of the House Homeland Security Committee. He was testifying with Charlie Allen who is our Chief Intelligence Officer at the department and also he was testifying with Dan Sutherland who is the Chief of the Office of Civil Rights and Civil DHS Data Privacy And Integrity Advisory Committee: March 21, 2007 Official Meeting Minutes Liberties, and the particular topic that they were talking about was the creation of fusion centers. I know that some of you may be familiar with these particular programs, but there are a number of fusion centers throughout the country. These are run on a state and local level. The idea is to bring together different resources on those levels to allow people from first responders to law enforcement on federal, state, local, tribal and even in some cases the consideration of bringing private sector folks from critical infrastructure in in order to allow there to be situation awareness, operational information‐sharing. And in that regard one of the things that weʹve begun to do is to look at the privacy issues associated with this collaborative environment. Obviously there are a number of issues with regard to the exchange of information and how that information will be exchanged in the processes in that vein. One of the things that we will be building upon is that the Department of Justice and the Department of Homeland Security have issued guidelines on how to implement a fusion center and in those guidelines are a number of different suggestions on how to build privacy practices into the creation of a fusion center.